ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1106×

20 examples

TechniqueUsed byProcedure example
T1106
Native API
GroupAPT38

APT38 has used the Windows API to execute code within a victim's system.

T1106
Native API
GroupSideCopy

SideCopy has executed malware by calling the API function `CreateProcessW`.

T1106
Native API
GroupKimsuky

Kimsuky has utilized Native APIs to collect data from victim hosts and facilitate execution of malicious scripts.

T1106
Native API
GroupGorgon Group

Gorgon Group malware can leverage the Windows API call, CreateProcessA(), for execution.

T1106
Native API
GroupmenuPass

menuPass has used native APIs including GetModuleFileName, lstrcat, CreateFile, and ReadFile.

T1106
Native API
GroupGamaredon Group

Gamaredon Group malware has used CreateProcess to launch additional malicious components.

T1106
Native API
GroupSandworm Team

Sandworm Team uses Prestige to disable and restore file system redirection by using the following functions: `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()`.

T1106
Native API
GroupMustang Panda

Mustang Panda has used various Windows API calls during execution and defense evasion.

T1106
Native API
GroupAPT37

APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection.

T1106
Native API
GroupHigaisa

Higaisa has called various native OS APIs.

T1106
Native API
GroupTropic Trooper

Tropic Trooper has used multiple Windows APIs including HttpInitialize, HttpCreateHttpHandle, and HttpAddUrl.

T1106
Native API
GroupBlackTech

BlackTech has used built-in API functions.

T1106
Native API
GroupTurla

Turla and its RPC backdoors have used APIs calls for various tasks related to subverting AMSI and accessing then executing commands through RPC and/or named pipes.

T1106
Native API
GroupTA505

TA505 has deployed payloads that use Windows API calls on a compromised host.

T1106
Native API
GroupChimera

Chimera has used direct Windows system calls by leveraging Dumpert.

T1106
Native API
GroupMedusa Group

Medusa Group has leveraged Windows Native API functions to execute payloads.

T1106
Native API
GroupToddyCat

ToddyCat has used `WinExec` to execute commands received from C2 on compromised hosts.

T1106
Native API
GroupLazarus Group

Lazarus Group has used the Windows API ObtainUserAgentString to obtain the User-Agent from a compromised host to connect to a C2 server. Lazarus Group has also used various, often lesser known, functions to perform various types of Discovery and Process Injection.

T1106
Native API
GroupSilence

Silence has leveraged the Windows API, including using CreateProcess() or ShellExecute(), to perform a variety of tasks.

T1106
Native API
GroupWIRTE

WIRTE has used the `RtlIpv4StringToAddressA` to convert IP-formatted string to a byte array.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.